Skip to content
Privacy

What ItemDocs stores, and what it doesn’t.

Customers never need an account to read a product page. Manufacturers own their content. Everything is hosted in the EU.

Last updated 5 October 2026.

Who we are

ItemDocs is operated by Nexivara, a sole proprietorship of Karan Bindal, D 102, Green Oak Apartment, Meera Marg, Banipark, Jaipur 302016, Rajasthan, India (GSTIN 08AWPPB6630G2ZH). For the data of manufacturers who use the Console, and for visitor analytics and security logs, Nexivara is the controller. For the details customers enter in a brand’s product registration form, the brand is the controller and ItemDocs processes them on the brand’s behalf (see below).

To reach us about privacy, use the contact form and mention “privacy” in your message. We answer within one month at the latest.

Customers scanning a QR code

  • Product pages need no account and set no cookies. They load no third-party scripts, fonts or trackers.
  • We count page opens, scans, which sections were opened and what was typed into the on-page search, with the device type (phone, tablet, desktop), country, language and the referring website’s domain. Your IP address is not stored. To count unique visitors per day we keep a keyed hash of the IP address and browser that changes every day, so visits on different days can’t be linked. Because the key is held by ItemDocs this is pseudonymous rather than anonymous data, and it is deleted after 13 months.
  • Please don’t type personal details into the on-page search: search terms are kept in the analytics so manufacturers can fill gaps in their content.
  • Videos from YouTube or Vimeo load only when you press play; until then no request goes to those services. After you press play, their privacy policies apply (YouTube is embedded in its privacy-enhanced mode).
  • If a brand offers product or warranty registration and you choose to fill in the form, your details (for example name, email, phone, purchase date, serial number, address and marketing consent) are stored for that brand and shown to it in its Console. The brand decides which fields to ask for and how long to keep them. ItemDocs never requires personal data to read a page.
  • A serial number you save on a product page with “Add serial number” stays in your browser only (see Cookies below); it is not sent to us.

Manufacturers using the Console

  • Your account: name, email address, a salted scrypt hash of your password, and whether your email address is confirmed.
  • Sessions: a hashed session token, when it was created and last used, and a device label such as “Chrome on macOS”. You can see and sign out each device in Settings.
  • Your organisation’s products, content, files, team members and pending invitations, and an activity log of changes (who did what, and when).
  • When online payments are live and you subscribe: a Stripe customer and subscription reference. Card details never reach ItemDocs.
  • Messages you send through the contact form: name, email, company, approximate number of products and your message.

Everything can be exported from Settings at any time as JSON. Owners can delete the organisation, and anyone can delete their own account. A deleted organisation is kept for 30 days in case it was a mistake, then permanently erased together with its files, analytics, registrations and the accounts of people who belong to no other organisation.

Cookies and browser storage

ItemDocs uses only what is strictly necessary, so there is no cookie banner:

  • itemdocs_session: keeps a manufacturer signed in to the Console. Set only after signing in; HTTP-only, secure, expires after 30 days without use or when you sign out.
  • A short-lived security cookie from our host’s firewall (Vercel) may be set only if your connection is challenged as possibly automated.
  • Browser storage (localStorage, never sent to us): on product pages, the language you chose or dismissed in the language suggestion, and a serial number you saved yourself. You can clear it in your browser settings at any time.

Where data is hosted, and by whom

All primary data is stored in the EU, in Frankfurt. We use these sub-processors:

Sub-processors
ProviderPurposeLocation of dataTransfer safeguard
Vercel Inc.Hosting, serverless functions, request logs, firewall and file storage (Vercel Blob)Functions and files in the Frankfurt region (fra1); content is cached at Vercel’s edge network worldwideUSA (company). EU Standard Contractual Clauses / EU-US Data Privacy Framework
Neon Inc.Database (all account, product, registration and analytics records)AWS eu-central-1, FrankfurtUSA (company). EU Standard Contractual Clauses
Zoho Corporation (ZeptoMail)Sending transactional emails: email confirmation, password reset, team invitations and registration confirmationsZoho data centres; message logs kept by ZeptoMail for a limited periodIndia / USA. EU Standard Contractual Clauses
Spaceship, Inc. and Zoho Corporation (Zoho Mail)Receiving email you send to hello@itemdocs.com: Spaceship forwards it, Zoho Mail stores it in our inboxSpaceship mail forwarding; Zoho data centresUSA / India. EU Standard Contractual Clauses
Vercel Inc. (Speed Insights)Anonymous page-performance measurements (Core Web Vitals) from the browser; no cookies, no IP addresses storedVercelUSA (company). EU Standard Contractual Clauses / EU-US Data Privacy Framework
Razorpay Software Private LimitedOnline plan payments. Card, UPI, bank and wallet details are entered in Razorpay’s own checkout and never reach ItemDocs; we receive the payment reference, amount and statusIndiaIndia. EU Standard Contractual Clauses

We announce new sub-processors on this page before they start processing personal data.

International transfers

Data is stored in the EU, but some providers above are US companies and can access it to run their service, and our own team may access it from outside the EU to provide support. Where personal data from the EU, EEA, UK or Switzerland is processed outside those areas, we rely on an adequacy decision (such as the EU-US Data Privacy Framework for certified providers) or the European Commission’s Standard Contractual Clauses, with additional technical safeguards: encryption in transit and at rest, and access limited to what is needed.

  • Contract: running a manufacturer’s account, organisation, team and subscription.
  • Legitimate interests: keeping the service secure (sessions, rate limits, firewall and request logs), aggregate page analytics so manufacturers can improve their content, and answering contact-form messages. You can object; see Your rights.
  • Legal obligation: invoices and tax records once payments are live.
  • Product registrations: the brand, as controller, decides the legal basis (usually the warranty contract, or your consent for marketing, which you give with the checkbox in the form).

How long data is kept

Retention periods
Console account (name, email, password hash)Until you delete your account (Settings → Delete my account), or 30 days after your last organisation is deleted.
Sign-in sessions30 days after last use, or until you sign out. Only a device label such as “Chrome on macOS” is kept, never your IP address.
Organisations, products, content and filesUntil the organisation is deleted, then 30 days for recovery, then permanently erased.
Product registrations (customer details)Decided by the manufacturer, who can export and delete them. Always erased with the manufacturer’s organisation (30 days after it is deleted).
Page analytics and on-page search terms13 months, then deleted automatically.
Activity log (who changed what)For the life of the organisation; erased with it.
Contact-form messagesAs long as needed to answer and follow up, and at most 12 months.
Rate-limit counters (contain an IP address or email)The length of the limit window, at most 1 hour.
Server request logs (contain IP addresses)Kept by Vercel for a short period (hours to a few days, depending on the plan).
Billing details, payments and tax invoicesEight years after the financial year of the invoice, as Indian GST and income-tax law require; kept even if the organisation is deleted.
Database backupsEncrypted, and expire after at most 30 days. Deleted data disappears from backups when they expire.

Your rights

Under the GDPR and similar laws you can ask for access to your data, a copy in a portable format, correction, erasure, restriction of processing, and you can object to processing based on legitimate interests. You can withdraw consent at any time.

  • Manufacturers: most of this is self-service. Edit your name in Settings, export everything with Export JSON, sign out devices, and delete your account or organisation. For anything else, use the contact form.
  • Customers who registered a product: contact the brand named on the product page; it controls your registration. If you can’t reach the brand, use our contact form with the product’s ItemDocs ID and we’ll forward your request or help the brand answer it.
  • Visitors: we hold no data that identifies you directly. Tell us the date and product if you want us to look for something specific.

We answer within one month. If you think we haven’t handled your data properly, you can complain to the data protection authority where you live or work.

For manufacturers: processing on your behalf

When customers register a product, your brand is the controller of their details and ItemDocs is your processor. Our Data Processing Agreement (GDPR Art. 28) is part of the Terms and applies automatically. In short: we process registrations only to store them and show them to you, keep them confidential and secured, use only the sub-processors listed above, help you answer customers’ requests, tell you without undue delay about a breach, and delete them when you delete them or your organisation.